Speedydowt Posted July 27, 2013 Posted July 27, 2013 (edited) Hey Everyone! Just wondering if anyone has implemented RADIUS based VLANs on their organisation/school, be very interested in how you did it! cheers Tom (wow it turned out I cannot spell Radius- sorry all!) Edited July 27, 2013 by Speedydowt
localzuk Posted July 27, 2013 Posted July 27, 2013 Yup, been running them for 5+ years here. We have IAS set up with a bunch of rules, the core switch (HP 5406zl) talks with that, and all the ports across the network are set to use aaa port-based mac address auth. Then, in our AD we have a username for each MAC address that's allowed on, and groups which match up with the IAS rules for each vlan. Some devices do not like this though (printers mostly) and have their vlan st statically on the switches. I'm pondering moving as much as I can over to 802.1x based auth though, using login names etc... We've started the move for Wi-Fi already.
Speedydowt Posted July 27, 2013 Author Posted July 27, 2013 This is awesome localzuk, how are you finding the 802.1x based vlans through wifi? Must be annoying to setup!
localzuk Posted July 27, 2013 Posted July 27, 2013 It works ok, the details are set by GPO for our windows 7 laptops. We're using a single vlan with multiple ssids at the moment but later this summer we're moving to 3 vlans. One which will be dedicated to 802.1x. The other 2 will be for guests and for non-802.1x devices but authenticated by the proxy.
DMcCoy Posted July 27, 2013 Posted July 27, 2013 No idea what is there now, but for a number of years (with XP, Vista, 7, os x, printers) I ran an entirely RADIUS vlan assigned network, wired and wireless. I combined this with the 5400 ACLs to have different server vlans available to different clients. All procurve with 802.1x for domain machine vlan assignment, MAC auth for printers and devices that don't support 802.1x and Apple machines (although now they have better 802.1x iirc). It worked pretty well, non auth machines ended up in an unauthenticated VLAN that only had WDS/mac imaging and domain join facilities. Gets around multicast on vlans with WDS as they all drop into the unauthenticated when network booting! Still some issues with windows 7 not holding netlogon for the auth, but it works nearly all the time. Only ever defeated by a phone system that had to have static vlan assignment, it was very quiet, never sent any traffic out when you plugged it into the network - no MAC gets seen for the switch to authenticate!
Speedydowt Posted July 28, 2013 Author Posted July 28, 2013 its really great that you guys actually have this setup, make me see the "light at the end of the tunnel". thanks very much for your insight!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now